Authentication Bypass in D-Link DSL/DIR/DNS Devices Exposes DNS Configuration
CVE-2026-0625
9.3CRITICAL
Key Information:
What is CVE-2026-0625?
Multiple D-Link DSL, DIR, and DNS devices have vulnerabilities in the dnscfg.cgi endpoint, allowing unauthorized access to the DNS configuration. Attackers exploiting this vulnerability can modify DNS settings without valid credentials, potentially leading to DNS hijacking attacks similar to past threats associated with the GhostDNS malware. With reported exploitation efforts observed in late 2025 and the end-of-life status of these products, it is crucial for users to be aware of the associated risks and discontinue the use of affected devices.
Affected Version(s)
DIR-600 0
DIR-608 0
DIR-610 0